[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SAP Crystal Reports - Information Disclosure Vulnerability

Author
Mohamed M.Fouad
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-32943
Category
web applications
Date add
02-07-2019
CVE
CVE-2019-0285
Platform
multiple
# Exploit Title: [Sensitive Information Disclosure in SAP Crystal Reports]
# Exploit Author: [Mohamed M.Fouad - From SecureMisr Company]
# Vendor Homepage: [https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=517899114]
# Version: [SAP Crystal Reports for Visual Studio, Version - 2010] (REQUIRED)
# Tested on: [Windows 10]
# CVE : [CVE-2019-0285]

POC:

1- Intercept the "Export" report http request

2- Copy the "__CRYSTALSTATE" + <crystal report user control> Viewer name parameter value. 

3- You will find a base64 value in "viewerstate" attribute. 

4- decode the value you will get database information such as: name, credentials, Internal Path disclosure and some debugging information.

#  0day.today [2024-09-28]  #